Metrics
Affected Vendors & Products
Mon, 09 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openclaw openclaw
|
|
| Weaknesses | CWE-290 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw openclaw
|
Fri, 06 Mar 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 06 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openclaw
Openclaw voice-call |
|
| Vendors & Products |
Openclaw
Openclaw voice-call |
Thu, 05 Mar 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook events by manipulating Forwarded or X-Forwarded-* headers in reverse-proxy configurations that implicitly trust these headers. | |
| Title | OpenClaw voice-call < 2026.2.3 - Webhook Verification Bypass via Forwarded Headers | |
| Weaknesses | CWE-345 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-03-05T21:59:41.870Z
Updated: 2026-03-10T13:04:19.487Z
Reserved: 2026-02-27T19:18:43.159Z
Link: CVE-2026-28465
Updated: 2026-03-09T17:51:14.093Z
Status : Analyzed
Published: 2026-03-05T22:16:19.593
Modified: 2026-03-09T16:26:00.910
Link: CVE-2026-28465
No data.
ReportizFlow